Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-11619MEDIUMDolibarr ERP CRM Legacy Filemanager config.inc.php improper authorizationEPSS 0.2%CVE-2025-46732MEDIUMOpenCTI's GraphQL IDOR enables authenticated users to modify or delete notifications of other usersEPSS 0.2%CVE-2018-9867—In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in EPSS 0.2%CVE-2026-83431MEDIUMVulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected aEPSS 0.2%CVE-2025-22170MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they inEPSS 0.2%CVE-2025-22177MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22174MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22173MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22168MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22172MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22176MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2026-14538MEDIUMBigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP ToolboxEPSS 0.2%CVE-2022-33705—Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permissionEPSS 0.2%CVE-2022-30717MEDIUMImproper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.EPSS 0.2%CVE-2025-46289MEDIUMA logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2.EPSS 0.2%CVE-2026-12213MEDIUMhcengineering Huly Platform User Information operations.ts getAccountInfo improper authorizationEPSS 0.2%CVE-2022-36838MEDIUMImplicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.EPSS 0.2%CVE-2026-18985HIGHEdit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093EPSS 0.2%CVE-2026-10211MEDIUMAstrBotDevs AstrBot fs.py _normalize_rw_path authorizationEPSS 0.2%CVE-2021-36311MEDIUMDell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privEPSS 0.2%